Skip to content

basalt / http/src / GUARDED_META_KEYS

Variable: GUARDED_META_KEYS ​

> const GUARDED_META_KEYS: readonly ["auth", "mfa", "can", "teamRole", "scopes", "subscribed", "feature"]

Defined in: http/src/guarded-meta.ts:24

The security-relevant route-meta keys the framework knows about. Each is enforced by a guard that a specific plugin registers:

  • auth, mfa — @basaltkit/auth's authPlugin
  • can — @basaltkit/permissions' permissionsPlugin
  • teamRole — @basaltkit/teams' teamsPlugin
  • scopes — @basaltkit/auth's apiKeysPlugin
  • subscribed, feature — @basaltkit/subscriptions' subscriptionsPlugin

Declaring one of these on a route is a request for protection; the guard is what enforces it. A route that declares a key nobody enforces would silently serve unprotected — the adapters therefore call assertRoutesGuarded at boot and fail loud instead.

Deliberately NOT in this set: central (a tenant-membership opt-out — a missing plugin removes a bypass, never a check), mcp (an exposure opt-in) and rateLimit (abuse throttling, not an authorization boundary, and legal to declare with securityPlugin's optional rate limiter switched off).

Released under the MIT License.